Privacy Policy
Draft — requires legal reviewLast updated September 28, 2026
This is a draft privacy policy prepared for legal review; it is not yet a reviewed or approved company privacy statement. It describes what the Stan application is designed to collect and how, so it can be checked against actual practice before a public launch.
What we collect
- Wallet addresses you connect or view, and on-chain transactions you submit. This data is public on Robinhood Chain regardless of Stan.
- When you claim creator fees: the challenge we gave you, the link to the public post (or the public bio or profile text) that carries it, and the result of our check. We read that public content from the platform (for X, via the third-party data provider twitterapi.io) only to confirm the challenge is there. We keep the post link, a hash of the text we checked and the result as evidence of the check; we do not keep more of the text than verification needs.
- Minimal public profile data from the platform (handle, display name, avatar) needed to show a creator reference.
- A wallet-session cookie, set after you sign a message with your wallet, that keeps you signed in as that wallet. It is strictly functional, httpOnly, expires automatically, and is cleared when you sign out.
- Basic operational logs (request metadata, rate-limit counters) used for abuse prevention.
What we do not do
- We do not request or store wallet seed phrases or private keys.
- We do not ask you to log in with a social account, and we never post or message on your behalf.
- We do not sell personal data.
Retention
We keep claim evidence for as long as the claim and any coin referencing that account exist, so that a claim can be reviewed or disputed. We aim to keep everything else to what is needed to run the app and prevent abuse.
Your controls
You can sign out of your wallet session at any time. Stan has no account to delete beyond that session: your wallet is your account. Public on-chain data (coin deployments, trades, claims) cannot be removed, since Stan does not control the blockchain. For anything else, use the report form.
Third parties
We read public posts and profiles from social platforms to verify claims, use twitterapi.io (a third-party service that receives the X handle being checked) to read public X data, and use Supabase for application data. Coins are created and traded on pons, an independent launchpad. Their handling of data is governed by their own policies.
Contact
Use the report form for privacy requests until a dedicated contact channel is published here.